Use-after-free in Qualcomm products - CVE-2021-1900

 

Use-after-free in Qualcomm products - CVE-2021-1900

Published: June 7, 2021


Vulnerability identifier: #VU53860
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-1900
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local application to escalate privileges on the system.

The vulnerability exists due to a boundary error in the Display subsystem. A local application can trigger a race condition while creating an external display and escalate privileges on the system.

Affected software

SD835
SDX55
SDX20
SDM630
SD855
SD845
SD712
SD710
SD675
SD670
SD450
SD636
QCA6174A
MSM8996AU
MSM8953
MSM8909W
MDM9650
MDM9206
APQ8096AU
APQ8053
APQ8017
QCA9377
SA6155P
QCS605
QCS405
QCA9379
APQ8009
QCA6574AU
WCD9326
SDX55M
SDX50M
SDX20M
SDW2500
SDM830
WCD9330
SD660
SD632
SD439
SD429
SD8CX
WCN3660B
WSA8815
WSA8810
WHS9410
WCN3999
WCN3998
WCN3990
WCN3980
WCN3950
WCN3680B
WCN3680
WCN3660
WCN3620
WCN3615
WCN3610
WCD9375
WCD9370
WCD9360
WCD9341
WCD9340
WCD9335
MDM9250
QCA6390
QCA6335
QCA6320
QCA6310
QCA6175A
QCA4020
QCA6420
CSRA6640
CSRA6620
AR8031
AQT1000
APQ8064AU
APQ8009W
SD455
SA8155P
SA8155
SA6155
Qualcomm215
QCS603
QCA9367
QCA6696
QCA6595AU
QCA6595
QCA6574A
QCA6574
QCA6564AU
QCA6564A
QCA6430
Google Android

How to mitigate CVE-2021-1900

Install updates from vendor's website.

Google Android - addressed in versions 8.1 2021-06-05, 9.0 2021-06-05, 10 2021-06-05, 11 2021-06-05

External References

Related Security Bulletins